CVE-2018-18621: XSS
CommuniGate Pro 6.2 allows stored XSS via a message body in Pronto! Mail Composer, which is mishandled in /MIME/INBOX-MM-1/ if the raw email link (in .txt format) is modified and then renamed with a .html or .wssp extension.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18621?
CVE-2018-18621 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2018-18621?
To fix CVE-2018-18621, upgrade CommuniGate Pro to a version that addresses the stored XSS vulnerability in the Pronto! Mail Composer.
Which versions of CommuniGate Pro are affected by CVE-2018-18621?
CVE-2018-18621 affects CommuniGate Pro version 6.2.
What is stored XSS as mentioned in CVE-2018-18621?
Stored XSS allows attackers to inject malicious scripts into web applications, which are then executed when other users view the affected content.
How does CVE-2018-18621 allow an attacker to exploit the system?
An attacker can exploit CVE-2018-18621 by modifying the raw email link and renaming it to a .html or .wssp extension, leading to execution of malicious scripts.